Skip to content
ISO 9001 ISO/IEC 27001 Proxmox Gold Partner Data in Italy
Rackone
News

Varnish Cache: how to speed up your website with a caching reverse proxy

Rackone systems team · 5 min read · Updated on

The Varnish Cache logo, a flying cartoon rabbit over a city skyline

Varnish Cache explained: how the caching reverse proxy speeds up your site, how to install it on Ubuntu or Debian and how to use it with WordPress.

If you run a blog, an online shop or a company website, loading speed is not a detail. Varnish Cache is an open source caching HTTP reverse proxy, also called a web accelerator: it sits in front of your web server, keeps the responses in memory and serves the next visitors from there, without asking the server to build the page again.

Why does website speed matter?

Loading speed affects three areas:

  • Search: Google recommends good Core Web Vitals, because they reflect what its core ranking systems seek to reward. The first of them, Largest Contentful Paint, is good at 2.5 seconds or less, and the server's response time is part of it.
  • Conversions: a slow page loses visitors before they read, buy or get in touch.
  • Credibility: a site that responds immediately appears more reliable than one that hesitates.

What does Varnish Cache do for your server?

Varnish has two advantages that still hold. It needs no changes to your code, on the server or in the pages. And it cuts the load on the server: after the first request, the following ones are answered from RAM until the cached copy expires, so the CPU does not rebuild the page and the disk does not reread the files. HTML pages, JavaScript, CSS and images all qualify.

The flow is simple: browser, Varnish, web server. When the page is in the cache, Varnish answers alone; when it is not, it asks the web server, stores the answer and passes it on. Content management systems such as WordPress, Drupal, Magento and PrestaShop build every page with PHP and database queries, which is where a cache in front of the server makes the biggest difference.

Varnish Cache or Vinyl Cache?

In September 2025 the open source project took the name Vinyl Cache. Varnish Software, the company behind the commercial edition, maintains a distribution of it that keeps the name Varnish Cache and adds built-in TLS. The configuration language and the way the cache works are the same in both: this guide follows the Varnish Cache installation guide.

How can you use Varnish Cache for your website?

To install Varnish you need root access to the server, as on a Linux VPS or a dedicated server: shared hosting does not allow it. The web server, Apache, Nginx or another, does not have to run on the same machine. Varnish calls it the backend, and with several backends it also works as a load balancer.

Its behaviour is written in VCL (Varnish Configuration Language), which can express very detailed rules. One thing has changed since this article first appeared: websites now run on HTTPS. Vinyl Cache does not handle TLS itself and sits behind a TLS proxy such as Hitch or HAProxy, which decrypts the traffic and passes it on; the Varnish Cache distribution can terminate TLS on its own. In both cases the certificate can be a free one from Let's Encrypt: see how a free SSL certificate works.

How to install and configure Varnish Cache

The commands follow the official guide for Debian and Ubuntu. On AlmaLinux and Rocky Linux the guide adds a repository file in /etc/yum.repos.d/ and installs with sudo dnf install varnish; the configuration steps are the same.

Step 1: add the Varnish repository

sudo apt-get install -y apt-transport-https curl gpg
sudo mkdir -p /etc/apt/keyrings/
curl -Ls https://packages.varnish-software.com/varnish/varnish.pub.asc | gpg --dearmor | sudo tee /etc/apt/keyrings/varnish.gpg > /dev/null
source /etc/os-release
echo "deb [signed-by=/etc/apt/keyrings/varnish.gpg] https://packages.varnish-software.com/varnish/$ID $VERSION_CODENAME main" | sudo tee -a /etc/apt/sources.list.d/varnish.list

Step 2: install Varnish

sudo apt-get update
sudo apt-get install varnish

Step 3: start Varnish and check it

sudo systemctl enable --now varnish
sudo systemctl status varnish
varnishd -V

The last command prints the installed version.

Step 4: put Varnish on port 80

By default Varnish listens on port 6081 and expects the web server on port 8080 of the same machine. Move your web server to port 8080 first, then open the service definition:

sudo systemctl edit --full varnish

and set the ExecStart line as in the official guide, with Varnish on port 80 and 2 GB of RAM for the cache:

ExecStart=/usr/sbin/varnishd \
          -a :80 \
          -a localhost:8443,PROXY \
          -f /etc/varnish/default.vcl \
          -P %t/%N/varnishd.pid \
          -p feature=+http2 \
          -s malloc,2g

The second -a line is where the TLS proxy hands over HTTPS traffic. Reload and restart:

sudo systemctl daemon-reload
sudo systemctl restart varnish

Step 5: the configuration file

The configuration lives in /etc/varnish/default.vcl. After installation it only says where the backend is:

vcl 4.1;

backend default {
    .host = "127.0.0.1";
    .port = "8080";
}

From here, VCL decides what to cache, for how long and what to leave out.

Varnish Cache and WordPress

By default Varnish does not cache requests that carry cookies or an authorisation header, nor responses that set a cookie. That protects logged-in users and shopping carts, but a site that sets a cookie on every page gains nothing. With WordPress the usual set-up is a VCL that ignores the cookies of anonymous visitors and keeps the admin area and the cart out of the cache, plus a purge plugin that removes a page from Varnish when you update it.

Installation is quick; tuning VCL for an application requires testing. Our systems engineers configure it within the systems management service (in Italian). If you would rather have hosting with Varnish already in place, our LAMP Cluster Cloud runs it in front of the application, and we use it in custom e-commerce hosting infrastructures, in Italian.

Choose a Linux VPS · Talk to an expert

Related articles

A blue cloud icon with a gold padlock in front of it, a symbol of a secure virtual server
News

How to secure a VPS in 5 steps

How to secure a VPS in 5 steps: SSH keys, a non-root user, a firewall with brute-force protection, tested backups and automatic security updates.

· 4 min read

Call Talk to an expert